Laws · GDPR ·art-25-par-1 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the processing, the controller shall, both at the time of the determination of the means for processing and at the time of the processing itself, implement appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation, in an effective manner and to integrate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects.
How it connects
Cited by
- Data Protection Commissioner v. Schrems and Facebook
- Data Protection Commissioner v. Schrems and Facebook
- Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020
- Guidelines 03/2022 on Deceptive design patterns in social media platform interfaces: how to recognise and avoid them
- UNICREDIT BANK SA: Insufficient technical and organisational measures to ensure information security
All 124
- Telecommunication service provide: Insufficient legal basis for data processing
- Telecommunication service provide: Insufficient legal basis for data processing
- T.K. EOOD: Insufficient technical and organisational measures to ensure information security
- L.E. EOOD: Insufficient technical and organisational measures to ensure information security
- Vodafone Italia S.p.A.: Non-compliance with general data processing principles
- Virgin Mobile Polska: Insufficient technical and organisational measures to ensure information security
- Robinson Tours Ltd. (Robinson Tours Idegenforgalmi és Szolgáltató Kft.): Insufficient technical and organisational measures to ensure information security
- ID Finance Poland Sp. z o.o.: Insufficient technical and organisational measures to ensure information security
- Krajowa Szkoła Sądownictwa i Prokuratury: Insufficient technical and organisational measures to ensure information security
- Planet Group Spa: Insufficient legal basis for data processing
- Irish Credit Bureau DAC: Insufficient technical and organisational measures to ensure information security
- Mercadona S.A.: Insufficient legal basis for data processing
- President of the Zgierz District Court: Insufficient technical and organisational measures to ensure information security
- Warsaw University of Technology: Insufficient technical and organisational measures to ensure information security
- Enel Energia S.p.A: Insufficient legal basis for data processing
- Cosmote Mobile Telecommunications S.A.: Insufficient technical and organisational measures to ensure information security
- Fortum Marketing and Sales Polska S.A.: Insufficient technical and organisational measures to ensure information security
- Budapest Bank Zrt.: Insufficient legal basis for data processing
- Telecommunications company: Insufficient technical and organisational measures to ensure information security
- Meta Platforms, Inc.: Non-compliance with general data processing principles
- Banca Comercială Română SA: Insufficient technical and organisational measures to ensure information security
- Bitfactor SRL: Insufficient technical and organisational measures to ensure information security
- Mayor: Insufficient technical and organisational measures to ensure information security
- Raiffeisen Bank SA: Insufficient technical and organisational measures to ensure information security
- Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security
- OTP LEASING ROMANIA IFN SA: Insufficient technical and organisational measures to ensure information security
- Casa Rusu S.R.L.: Insufficient technical and organisational measures to ensure information security
- Viking Line Oy Abp: Non-compliance with general data processing principles
- Douglas Italia S.p.a.: Non-compliance with general data processing principles
- Edison Energia S.p.A.: Non-compliance with general data processing principles
- Szczecin-Centrum District Court: Insufficient technical and organisational measures to ensure information security
- Azienda sanitaria locale di Bari: Non-compliance with general data processing principles
- Company: Insufficient technical and organisational measures to ensure information security
- AUTOMOBILE BAVARIA SRL: Insufficient technical and organisational measures to ensure information security
- Sports betting operator: Insufficient legal basis for data processing
- Municipality: Insufficient technical and organisational measures to ensure information security
- Piraeus Bank: Non-compliance with general data processing principles
- NOVA TELECOMMUNICATIONS & MEDIA ΜΟΝΟΠΡΟΣΩΠΗ Α.Ε.,: Insufficient fulfilment of data subjects rights
- Municipality: Insufficient technical and organisational measures to ensure information security
- Company: Insufficient technical and organisational measures to ensure information security
- Azienda Usl Toscana Sud Est.: Non-compliance with general data processing principles
- TikTok Limited: Non-compliance with general data processing principles
- Company: Insufficient technical and organisational measures to ensure information security
- Compara Facile S.r.l.: Non-compliance with general data processing principles
- Athens Urban Transport Organization: Non-compliance with general data processing principles
- Norwegian Labor and Welfare Administration: Insufficient technical and organisational measures to ensure information security
- Polish Minister of Health: Insufficient technical and organisational measures to ensure information security
- Disciplinary officer: Insufficient technical and organisational measures to ensure information security
- Website operator: Insufficient fulfilment of data subjects rights
- Res-Gastro M. Gaweł Sp. k.: Insufficient technical and organisational measures to ensure information security
- Committee: Insufficient technical and organisational measures to ensure information security
- Healthcare facility: Insufficient technical and organisational measures to ensure information security
- Your Consulting SRL: Insufficient technical and organisational measures to ensure information security
- Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security
- POLAND DPA: Insufficient technical and organisational measures to ensure information security
- Sambla Group Oy: Insufficient technical and organisational measures to ensure information security
- Centrum Medyczne Ujastek Sp. z o.o.: Non-compliance with general data processing principles
- Hospital: Non-compliance with general data processing principles
- Luka Inc.: Non-compliance with general data processing principles
- Company: Non-compliance with general data processing principles
- S.P.E.E.H. HIDROELECTRICA S.A: Insufficient technical and organisational measures to ensure information security
- Unicredit Bank SA: Insufficient technical and organisational measures to ensure information security
- FARMEC SA: Insufficient technical and organisational measures to ensure information security
- Vodafone Romania S.A.: Insufficient technical and organisational measures to ensure information security
- Alliance for the Union of Romanians Party: Non-compliance with general data processing principles
- McDonald’s Polska Sp. z o.o.: Non-compliance with general data processing principles
- 24/7 Communication Sp. z o.o.: Insufficient technical and organisational measures to ensure information security
- Non-Public Health Care Institution: Insufficient technical and organisational measures to ensure information security
- S-Pankki Oyj: Insufficient technical and organisational measures to ensure information security
- Aktia Pankki Oyj: Insufficient technical and organisational measures to ensure information security
- Hestia Publishers & Booksellers I. D. Kollaros & Co. S.A.: Insufficient technical and organisational measures to ensure information security
- Municipality of Moschato–Tavros: Insufficient legal basis for data processing
- Cucina di Fabio S.R.L.: Insufficient legal basis for data processing
- hier
- Guidelines 02/2025 on processing of personal data through blockchain technologies
- Opinion 3/2025 on the draft decision of the French Supervisory Authority (FR SA) regarding the “Lexing GDPR certification criteria”
- EDPB Annual Report 2024
- Guidelines 3/2025 on the interplay between the DSA and the GDPR
- Data Protection Commissioner v Facebook Ireland and Maximillian Schrems
- Deutsche Wohnen SE v Staatsanwaltschaft Berlin
- Powiatowego Inspektora Sanitarnego w Policach: Insufficient technical and organisational measures to ensure information security
- UODO fines accounting firm €2,760 for email breach security failures
- UODO reprimands electricity seller for Art. 5, 24, 25, 28, 32 GDPR violations over
- Your Consulting SRL: Insufficient technical and organisational measures to ensure information security
- Chief Constable of the Police Service of Scotland: Insufficient technical and organisational measures to ensure information security
- National Bank of Greece S.A: Insufficient technical and organisational measures to ensure information security
- If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation
- UODO (Poland) - DKN.5131.27.2023
- Garante per la protezione dei dati personali (Italy) - 487/2026
- Guidelines on processing of personal data through blockchain technologies
- Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models
- Statement 2/2024 on the financial data access and payments package
- Opinion 11/2024 on the use of facial recognition to streamline airport passengers’ flow (compatibility with Articles 5(1)(e) and(f), 25 and 32 GDPR)
- Report of the work undertaken by the ChatGPT Taskforce
- EDPB Annual Report 2023
- Opinion 08/2024 on Valid Consent in the Context of Consent or Pay Models Implemented by Large Online Platforms
- EDPB-EDPS Joint Opinion 02/2023 on the Proposal for a Regulation of the European Parliament and of the Council on the establishment of the digital euro
- EDPB-EDPS Joint Opinion 01/2023 on the Proposal for a Regulation of the European Parliament and of the Council laying down additional procedural rules relating to the enforcement of Regulation (EU) 2016/679
- EDPB Annual Report 2021
- X v Russmedia Digital SRL and Inform Media Press SRL
- Criminal proceedings against V.S
- Robert Roos and Others v European Parliament
- European Commission v Kingdom of Spain
- Tele2 (Netherlands) BV and Others v Autoriteit Consument en Markt (ACM)
- United Kingdom of Great Britain and Northern Ireland v European Parliament and Council of the European Union
- General Data Protection Regulation (GDPR) – Revolution Coming to European Data Protection Laws in 2018. What’s New for Ordinary Citizens?
- Aurelia Tamò-Larrieux, Designing for Privacy and its Legal Framework: Data Protection by Design and Default for the Internet of Things
- UODO reprimands hospital for inadequate processor oversight and email security failures
- ANSPDCP (Romania) - Fine against Orange Romania SA of July 17, 2026
- DSB (Austria) - 2025-0.950.759
- UODO (Poland) - DKN.5131.5.2025
- US Zagreb - Us I-4772/2023-10
- EWCA (UK) - 2026 EWCA Civ 1130
- Orange Romania SA: Insufficient technical and organisational measures to ensure information security
- Friuli Centrale University Health Authority: Insufficient technical and organisational measures to ensure information security
- Finnish DPA finds 12-year retention of rental applicant data violates minimisation
- AEPD sanctions Vodafone España for inadequate Super WiFi processor agreement and oversight
- Sole trader providing accounting and tax advisory services: Insufficient technical and organisational measures to ensure information security
- District Governor of Lubartów: Insufficient technical and organisational measures to ensure information security
Related across sources
C-77/21 Digi Távközlési és Szolgáltató Kft. v Nemzeti Adatvédelmi és Információszabadság Hatóság In this preliminary ruling, the CJEU interpreted Articles 5(1)(b) and 5(1)(e) GDPR in proceedings between Digi Távközlési és Szolgáltató Kft. and the Hungarian National Authority… CJEU ·First Chamber Oct 20, 2022 Retention Period Storage Limitation Personal Data
C-268/21 Norra Stockholm Bygg AB v Per Nycander AB In Case C-268/21, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Swedish Supreme Court in proceedings between Norra Stockholm… CJEU ·Third Chamber Mar 2, 2023 Retention Period Anonymization Personal Data
C-175/20 SIA 'SS' v Valsts ieņēmumu dienests In Case C-175/20, the Court of Justice of the EU interpreted GDPR Articles 5 and 6 in response to a preliminary ruling from the Latvian Regional Administrative Court concerning a… CJEU ·Fifth Chamber Feb 24, 2022 Retention Period Personal Data Legitimate Interest
C-446/21 Maximilian Schrems v Meta Platforms Ireland Limited In a preliminary ruling arising from proceedings between Maximilian Schrems and Meta Platforms Ireland Limited, the Court of Justice of the European Union interpreted GDPR… CJEU ·Fourth Chamber Oct 4, 2024 Retention Period Personal Data Marketing
Guidelines 01/2022 data subject rights - Right of access Guidelines ·EDPB Apr 17, 2023 Right of Access Personal Data Right to Rectification
Guidelines 1/2020 processing personal data in the context of connected vehicles and mobility related applications Guidelines on processing of personal data through video devices Guidelines ·EDPB Jan 28, 2020 Personal Data Privacy by Design & Default Processing